Getting Data In

How to correlate two sourcetypes on a single field?

pjb2160
Path Finder

I wish to correlate two sourcetypes on a single field which I would expect should look something like this:

(sourcetype=type_1 changed_user=*) OR (sourcetype=type_2 users_affected=*) | where changed_user=users_affected | table changed_user, users_affected

Unfortunately this returns no results when I know there are matching results. I have created sample data with "John Smith" appearing in each.

I should also mention that users_affected is likely to have one or more users listed whereas changed_user will only ever have one user listed.

In trying to resolve this I was initially looking for exact matches (on "John Smith") so if anyone knows how I can get this query to first work on an exact match then working to include results where changed_user "exists in" type_2 users_affected that would be much appreciated!

happy to explain further if my intention is not clear!

cheers

Tags (2)
0 Karma

vasanthmss
Motivator

MuS
Legend

I second the second answer 🙂

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...